Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Tesla adds ‘ribs’, other stats to track how often drivers use Full Self-Driving software

Microsoft is working on yet another OpenClaw-like agent

X brings voice memos back to X Chat

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Microsoft is working on yet another OpenClaw-like agent

    14 April 2026

    OpenAI has acquired AI personal finance startup Hiro

    14 April 2026

    Largest orbital computing cluster is open for business

    13 April 2026

    Anthropic restricts Mythos traffic to protect the Internet — or does Anthropic?

    12 April 2026

    Sam Altman responds to ‘inflammatory’ New Yorker article after his home was attacked

    12 April 2026
  • Apps

    X brings voice memos back to X Chat

    14 April 2026

    Avec’s Tinder-style email app lets you swipe through your inbox

    14 April 2026

    Roblox introduces ‘Kids’ and ‘Select’ accounts for age-appropriate access to games and chats

    13 April 2026

    You can now edit your comments on Instagram

    13 April 2026

    Meta AI app climbs to No. 5 in App Store after release of Muse Spark

    12 April 2026
  • Crypto

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025
  • Fintech

    Cash app launches ‘pay later’ feature for P2P transfers

    3 April 2026

    Doss raises $55 million for AI inventory management that connects to ERP

    24 March 2026

    Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

    23 March 2026

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026
  • Hardware

    Amazon is ending support for older Kindle devices

    9 April 2026

    Intel signs Elon Musk’s Terafab chip project

    8 April 2026

    The Xiaomi 17 Ultra has some impressive extras that make taking photos really fun

    6 April 2026

    In Japan, the robot doesn’t come for your job. fills the one no one wants

    6 April 2026

    Peter Thiel’s big bet on solar-powered cow collars

    5 April 2026
  • Media & Entertainment

    X says he’s reducing payouts to clickbait accounts

    12 April 2026

    TechCrunch is headed to Tokyo — and it’s bringing the Startup Battlefield with it

    10 April 2026

    Spotify now allows everyone to turn off videos in its app

    9 April 2026

    As YouTube expands into TV, it sees more interactive video across all formats

    9 April 2026

    Tubi is the first streamer to launch a native app on ChatGPT

    8 April 2026
  • Security

    Anodot hack leaves over a dozen compromised companies facing extortion

    14 April 2026

    Booking.com confirms that hackers accessed customer data

    13 April 2026

    Convicted spyware maker Bryan Fleming avoids jail time on conviction

    12 April 2026

    The Trump administration plans to cut the cybersecurity agency’s budget by $700 million

    11 April 2026

    Russian government hackers broke into thousands of home routers to steal passwords

    11 April 2026
  • Startups

    Walmart-owned Flipkart, Amazon are squeezing India’s e-commerce startups

    12 April 2026

    This founder helped build SpaceX’s most powerful rocket engine. Now he’s building a “fighter for orbit.”

    12 April 2026

    Sierra’s Bret Taylor says the era of button-clicking is over

    11 April 2026

    After the data breach, the $10 billion startup Mercor is one month old

    11 April 2026

    What founders can learn from Anjuna’s layoffs and recovery

    10 April 2026
  • Transportation

    Tesla adds ‘ribs’, other stats to track how often drivers use Full Self-Driving software

    14 April 2026

    Uber and Nuro begin testing premium robotaxi service in San Francisco

    14 April 2026

    Slate Auto raises $650 million to fund its affordable EV truck plans

    13 April 2026

    TechCrunch Mobility: Who’s chasing all the self-driving talent?

    13 April 2026

    Slate Auto: Everything you need to know about the Bezos-backed EV startup

    12 April 2026
  • Venture

    Vercel CEO Guillermo Rauch signals IPO readiness as AI agents drive revenue

    14 April 2026

    Nvidia-backed SiFive hits $3.65 billion valuation for open AI chips

    11 April 2026

    How to make the Startup Battlefield Top 20 — and what each company gets regardless

    10 April 2026

    Collide Capital Raises $95M to Back Future-of-Work Fintech Startups

    9 April 2026

    VC Eclipse has a new $1.3 billion fund to back — and build — “natural AI” startups

    8 April 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Hundreds of Snowflake customer passwords found online linked to information-stealing malware
Security

Hundreds of Snowflake customer passwords found online linked to information-stealing malware

techtost.comBy techtost.com6 June 202408 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Hundreds Of Snowflake Customer Passwords Found Online Linked To Information Stealing
Share
Facebook Twitter LinkedIn Pinterest Email

Cloud data analytics company Snowflake is at the center of a recent wave of alleged data thefts as its enterprise customers try to figure out if their cloud data stores have been compromised.

Snowflake helps some of the world’s largest companies – including banks, healthcare providers and technology companies – store and analyze massive amounts of data, such as customer data, in the cloud.

Last week, Australian authorities sounded the alarm saying they were aware of “successful compromises of several companies using Snowflake environments,” without naming the companies. The hackers had claimed on a well-known cybercrime forum that they had stolen hundreds of millions of customer records from Santander Bank and Ticketmaster, two of Snowflake’s biggest customers. Santander confirmed database breach “hosted by a third party provider”, but does not name that provider. On Friday, Live Nation confirmed that its Ticketmaster subsidiary had been hacked and that the stolen database was hosted on Snowflake.

Snowflake recognized in a brief statement that it was aware of “potentially unauthorized access” to a “limited number” of customer accounts, without specifying which ones, but that it found no evidence of a direct breach of its systems. Instead, Snowflake called it a “targeted campaign targeting users with single-factor authentication” and that the hackers used “previously purchased or information-stealing malware” designed to scrape a user’s saved passwords from his computer.

Despite the sensitive data Snowflake maintains about its customers, Snowflake allows each customer to manage the security of their environment and does not automatically enroll or require its customers to use multi-factor authentication or MFA; according to the Snowflake customer documentation. Not enforcing the use of MFA appears to be how cybercriminals allegedly obtained massive amounts of data from some Snowflake customers, some of whom were setting up their environments without the added security measure.

Snowflake admitted that one of its own “demo” accounts was compromised because it was not protected beyond a username and password, but claimed that the account “did not contain any sensitive data”. It is unclear if this stolen demo account has any role in the recent breaches.

TechCrunch this week saw hundreds of alleged Snowflake customer credentials available online for cybercriminals to use as part of hacking campaigns, suggesting that the risk of Snowflake customer account compromises may be much greater than first known.

The credentials were stolen by malware infecting the computers of employees accessing their employer’s Snowflake environment.

Some of the credentials seen by TechCrunch appear to belong to employees at companies known to be customers of Snowflake, including Ticketmaster and Santander, among others. Employees with access to Snowflake include database engineers and data analysts, some of whom report their experience using Snowflake on their LinkedIn pages.

For its part, Snowflake has told customers to immediately enable MFA for their accounts. Until then, Snowflake accounts that don’t enforce the use of MFA to sign in leave their stored data at risk of being compromised by simple attacks like password theft and reuse.

How we checked the data

A source with knowledge of cybercriminal activity directed TechCrunch to a site where would-be attackers can search for lists of credentials stolen from various sources, such as stealing malware on someone’s computer or collecting from previous data breaches. (TechCrunch does not link to the site where stolen credentials are available, so as not to help bad actors.)

In total, TechCrunch has seen more than 500 credentials containing employee usernames and passwords, along with the web addresses of the login pages for the corresponding Snowflake environments.

The exposed credentials appear to be Snowflake environments owned by Santander, Ticketmaster, at least two pharmaceutical giants, a food delivery service, a public freshwater supplier and others. We also saw exposed usernames and passwords allegedly belonging to a former Snowflake employee.

TechCrunch is not naming the former employee because there is no evidence they did anything wrong. (It is ultimately the responsibility of both Snowflake and its customers to implement and enforce security policies that prevent intrusions resulting from the theft of employee credentials.)

We didn’t test for stolen usernames and passwords, as doing so would break the law. Therefore, it is unknown if the credentials are currently in use or if they directly led to account breaches or data theft. Instead, we worked to verify the authenticity of exposed credentials in other ways. This includes checking the individual login pages of the Snowflake environments exposed by the information-stealing malware, which was still active and connected at the time of writing.

The credentials we’ve seen include the employee’s email address (or username), their password, and the unique web address to log into their company’s Snowflake environment. When we checked the web addresses of Snowflake environments — which are often made up of random letters and numbers — we found that registered Snowflake customer login pages are publicly accessible, even if they are not searchable online.

TechCrunch has confirmed that the Snowflake environments correspond to the companies whose employee credentials were compromised. We were able to do this because every login page we checked had two separate options to log in.

One way to sign in is based on Okta, a single sign-on provider that allows Snowflake users to sign in with their company’s corporate credentials using MFA. In our checks, we found that these Snowflake login pages were redirected to the Live Nation (for Ticketmaster) and Santander login pages. We also found a set of credentials belonging to a Snowflake employee whose Okta login page still redirected to an internal Snowflake login page that no longer exists.

The other Snowflake login option allows the user to use only their Snowflake username and password, depending on whether the enterprise customer enforces MFA on the account, as described by Snowflake’s own support documentation. It is these credentials that appear to have been stolen by the malware stealing information from employees’ computers.

It’s unclear exactly when the employees’ credentials were stolen or how long they were online.

There is some evidence to suggest that several employees with access to their company’s Snowflake environments have previously had their computers compromised by information-stealing malware. According to an audit for the breach notification service Have I Been Pwned, several of the corporate email addresses used as usernames to access Snowflake environments were found in a recent data dump containing millions of stolen passwords is scraped from various Telegram channels used to share stolen passwords.

Snowflake spokeswoman Danica Stanczak declined to answer specific questions from TechCrunch, including whether any of its customers’ data was found in the Snowflake employee’s test account. In a statement, Snowflake said it is “suspending some user accounts where there is strong evidence of malicious activity.”

Snowflake added: “Under Snowflake’s shared responsibility model, customers are responsible for enforcing MFA with their users.” The spokesperson said that Snowflake is “looking at all options for enabling MFA, but we have not finalized any plans at this time.”

When reached by email, Live Nation spokeswoman Kaitlyn Henrich had no comment as of press time.

Santander did not respond to a request for comment.

The lack of MFA has resulted in massive breaches

Snowflake’s response so far leaves many questions unanswered and reveals a number of companies that are not reaping the benefits that MFA security provides.

What is clear is that Snowflake bears at least some responsibility for not requiring its users to enable security mode, and now bears the brunt of it — along with its customers.

The data breach at Ticketmaster reportedly involved more than 560 million customer records, according to cybercriminals who advertised the data online. (Live Nation would not comment on how many customers are affected by the breach.) If proven, Ticketmaster would be the largest data breach in the US so far this year and one of the largest in recent history.

Snowflake is the latest company in a series of high-profile security incidents and major data breaches caused by a lack of MFA.

Last year, cybercriminals deleted about 6.9 million customer records from 23andMe accounts that weren’t protected without MFA, prompting the genetic testing company — and its competitors — to require users to enable MFA by default to prevent a repeat attack.

And earlier this year, UnitedHealth-owned health tech giant Change Healthcare admitted hackers broke into its systems and stole massive amounts of sensitive health data from a system not protected by MFA. The healthcare giant has not yet said how many people had their information breached, but said it was likely to affect a “significant percentage of people in America”.


Do you know more about Snowflake account hacks? Getting in touch. To contact this reporter, please contact Signal and WhatsApp at +1 646-755-8849 or via email. You can also send files and documents via SecureDrop.

cloud customer cyber security data breach hundreds informationstealing linked malware online passwords Santander Snowflake TicketMaster
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDealt turns retailers into service providers and proves that pivots sometimes work
Next Article Amazon buys Indian video streaming service MX Player
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Anodot hack leaves over a dozen compromised companies facing extortion

14 April 2026

Booking.com confirms that hackers accessed customer data

13 April 2026

Anthropic restricts Mythos traffic to protect the Internet — or does Anthropic?

12 April 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Tesla adds ‘ribs’, other stats to track how often drivers use Full Self-Driving software

14 April 2026

Microsoft is working on yet another OpenClaw-like agent

14 April 2026

X brings voice memos back to X Chat

14 April 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Cash app launches ‘pay later’ feature for P2P transfers

3 April 2026

Doss raises $55 million for AI inventory management that connects to ERP

24 March 2026

Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

23 March 2026
Startups

Walmart-owned Flipkart, Amazon are squeezing India’s e-commerce startups

This founder helped build SpaceX’s most powerful rocket engine. Now he’s building a “fighter for orbit.”

Sierra’s Bret Taylor says the era of button-clicking is over

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.